logoalt Hacker News

kwar13today at 2:24 AM3 repliesview on HN

Would've been good if it named the hosting provider. That's the most informative part.


Replies

r1chtoday at 4:39 AM

Every shared hosting provider has this risk. Critical projects should be using dedicated or VPS hosting, preferably with encrypted filesystems too as even datacenter techs can fall victim to social engineering.

I'm pretty surprised that they got away with unsigned updates and shared hosting as long as they did. I wonder how many similar popular projects are out there on dodgy infrastructure.

Larrikintoday at 2:36 AM

Maybe the hosting provider is currently undergoing an audit or implementing the changes?

I expect to know it one day, but it may be too early to provide the name now.

nickorlowtoday at 4:03 AM

Lawsuits are expensive and I'd think that name and shaming would open npp up to one